Blake Buchert
References

What the teams
said afterward.

Engineering leaders, security owners, and research peers, in their own words. Anyone here is happy to take a reference call.

He found the failure we had convinced ourselves was theoretical, then wrote the test that keeps it from coming back.
Ian HaddadSecurity Lead, Halden Systems — signed weights engagement, 2025

Engineering leaders

Clients and colleagues
Northgate Labs — agent red team
We hired Blake for two weeks of prompt injection testing and kept him for the quarter. On day three he refunded a fictional customer's invoice using nothing but text hidden in a help-center article one of our partners could edit. That demo ended an argument our team had been having for months, and the confirmation step shipped the following sprint.
Jackson LeonardVP Engineering, Northgate Labs
Corvid AI — detection platform
Blake joined a platform team that was skeptical of outside security help and left with three of our engineers using his tooling by choice. His detections are still running a year later, untouched, which is the only measure of this work I trust.
Theo WallaceDirector of ML Infrastructure, Corvid AI
Meridian Pay — threat review
We came to him with an architecture we thought was nearly done. He asked four questions, drew the trust boundaries we had skipped, and we redesigned the session model before a line of it reached production. Every finding arrived with a fix we could schedule against real sprints.
Rafe BradshawCISO, Meridian Pay
Halden Systems — supply chain
Two weeks after our policy gate went live it blocked an unsigned experimental checkpoint headed for production traffic. That is an incident that never happened, and it is the clearest return I can point to from any security engagement we have run.
Ian HaddadSecurity Lead, Halden Systems

Research peers

Collaborators and reviewers
Fine-tune poisoning research
I cite Blake's poisoning numbers in nearly every design review I run. He took a risk teams were writing off as academic and made it concrete enough to budget against, then published the dataset so the rest of us could check him.
Dr. Priya RaghunathanResearch Lead, Vector Institute for Applied Security
Vector Summit programme committee
Blake submitted the best-argued talk in the track and then spent the conference in the hallway helping other people's teams. He is the reviewer I send borderline agent-security papers to, because he will tell an author the uncomfortable thing kindly.
Marcus OyelaranProgramme Chair, Vector Summit

Teams he trained

Workshops and enablement
Two-day workshop, 30 engineers
Our product engineers walked in expecting a lecture about jailbreaks and walked out with a logging checklist they had written themselves. Six months on, the phrase 'treat the tool result as untrusted' shows up unprompted in our pull request reviews.
Elena VasquezHead of Platform, Arboretum Health
Internal red team program
He set up our exercise program and then deliberately made himself unnecessary — templates, a rotation schedule, and a debrief format the team still follows. Most consultants build dependence. Blake built capability and handed us the keys.
Daniel OkonkwoDirector of Security Engineering, Halden Systems

Shorter notes

Fastest I have seen someone go from reading our architecture doc to finding a real problem in it. Sofia LindqvistStaff Engineer, Corvid AI
Writes findings an engineer can act on the same week. No theater, no severity inflation. Grant WhitfieldEngineering Manager, Northgate Labs
The only external tester whose report our on-call team read voluntarily, start to finish. Amara BoatengSRE Lead, Meridian Pay
Calm in a room full of people who are wrong, including sometimes me. Good instinct for which fight matters. Tobias FreiCTO, Arboretum Health

Talk to any of them.
Then talk to me.